https://www.w3.org/TR/CSP2/#directive-base-uri I would also suggest adding `base-uri 'none';` to the examples because it _does not_ fallback to `default-src`.